>https://security-tracker.debian.org/tracker/CVE-2025-48387
>https://dgl.cx/2025/07/git-clone-submodule-cve-2025-48384
>tl;dr: On Unix-like platforms, if you use git clone --recursive on an untrusted repo, it could achieve remote code execution. Update to a fixed version of git and other software that embeds Git (including GitHub Desktop).